The NIS2 Directive, specifically in Article 6, Point 1, defines “network and information systems” as:
- (a) an electronic communications network as defined in point (1) of Article 2 of Directive (EU) 2018/1972;
- (b) any device or group of interconnected or related devices, one or more of which, pursuant to a program, perform automatic processing of digital data; or
- (c) digital data stored, processed, retrieved or transmitted by elements of the devices referred to in points (a) and (b) for the purposes of their operation, use, protection and maintenance.
This definition includes three main elements:
- Traditional electronic communications networks as defined by EU legislation.
- Individual or interconnected devices capable of performing automatic processing of digital data, including a wide range of computing devices.
- The digital data itself, encompassing its various states (stored, processed, retrieved, transmitted) and its connection to the operation, use, protection, and maintenance of the aforementioned networks and devices.
This comprehensive definition ensures that the NIS2 Directive covers the vast range of systems and data fundamental to modern businesses and organizations across various sectors. Understanding which assets fall within this scope is the first step in assessing if and how your organization is subject to NIS2 compliance obligations. For a deeper dive into the general framework, you can also consult what the main objective of the NIS2 Directive is.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
